logo

The RingHopper Journey or How We Almost Zero-day’d the World

Conference:  Defcon 31

2023-08-01

Authors:   Benny Zeltser Security Research Team Lead, Intel, Jonathan Lusky Security Research Team Lead, Cellebrite


Abstract

Last year we almost zero-day’d the world with the publication of RingHopper. Now we can finally share some juicy details and invite you for an illuminating journey as we delve into the realm of RingHopper, a method to hop from user-land to SMM. We will survey the discovery and disclosure of a family of industry-wide vulnerabilities in various UEFI implementations, affecting more than eight major vendors, making billions of devices vulnerable to our attack. Then, we will deep-dive into the innards of SMM exploitation and discuss methods to use and abuse various functionalities and properties of edk2 to gain code execution. We will unveil both our futile and fruitful quests of crafting our way to SMM, and detail both the paths that lead to dead-ends, and the route to success. We will give a detailed overview of different ways to elevate this kind of attack to user-land both on Windows and Linux by chaining multiple vulnerabilities together. Finally, we will show RingHopper hopping from user-space to… SMM.

Materials: